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Translate this text 

Methods and apparatus are 
presented for providing local 
authentication of subscribers 

travelling outside their home systems. , > 

A subscriber identification token (230) 
provides authentication support by 
generating a signature (370) based 

upon a key that is held secret from a s : . *- 

mobile unit (220). A mobile unit (220) " * 

that is programmed to wrongfully 

retain keys from a subscriber * ; ^ ^ 

identification token (230) after a 

subscriber has removed his or her 

token is prevented from subsequently 

accessing the subscriber's account. 
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(visited) -/XrA (VS) 2 1 0 ft T 5 ^ 



I L T ^ S tin A # * §S IE T 3 ft 46 © -ft ?£ * 

2 o o © IS ii ^ M !t L T § tin A # f± M 
J ft f* a - -y h 2 2 0 £ ffl f 3 o tin A # f± tin A 
df*^---y h 2 2 o^iMfS„ ^ © £ d % tin A 

* m Wl h - ? y li , tin A # fr M K 5fc y X r A fr L ^ n ft * m M T Z> & S M L t n ft •y- - 
e X ic 7 V -tr X f 3 d £ * rT f£ £ f 3 , ft ^ & M II If IS * £ T 3 J; 5 t if ^ * ft 3 0 

( H ^ 2 ft ft IE ^§ ) li&mfo3--v h 2 2 0fr?>^-H'X©/:i6<DV S 2 1 0fcI5 
ftSo VS 2 1 0 i± tin A # (H^-^-f) '\©^-t:x^^£t? j;5£HS 2 0 0 i; 3S ft 

[00 1 7 ] 

H S 2 0 Oti7>nf>/^- 2 4 0 £ tin A # ft g'J h - ? y ± t fS W 2 ft ft $5 ffi If IS © ft] 
m (knowledge) Ic M ~J ^ ft ^ W JS ^ (expected response) (XRES) 2 7 0 
So ^ y $ h. ~f y ^ — 2 4 0 t± f- y v> (chal lenge) il L T fS ffl 2 ft £ ^ # V & <9 , d 
d g *8 i; 2 ft ft (targeted) S ffi A f± ^ ffl JS g 2 7 OtY-y f t3l|j5S*5i4t5/i: 

fefe:7^^At>^-2 4 0£$5®fiDftliIli££ffifflT3 o ? y ? k~r y — 2 4 0 & £i X 

RE S 2 7 OtiHS 2 0 Oi^VS 2 1 Otlf ?n? 0 ffi © If IS )S {§ 2 ft § fr\ d d 
f± M $ fr % ^ ( H Tjk •£ f ) o H S 2 0 0 t V S 2 1 0 t <D fS <D W it f± H 1 \C IE $ * ft ft 

ft&vt&^icz n% o vs2 i oiiiiftaz7 i- 2 2 ot7y^Af 4 

it L T , Wfta - 7 F 2 2 0 ^5(011^7*-^ 2 6 OOil^lO, fit M * V * ~ 
-?2 6 OfcXRE S 2 7 0 t (i V S 2 1 0 it K fg ? 2 8 0 it $e 2 ft 3 0 & L & fit §g ^ 
7t-> i 2 6 0 J:XRES 2 7 0 t*W7ftft(f, V S 2 1 0 lillfta^ 7 h 2 2 0 

[0018] 

H ft {* ^ - ~y h 2 2 0 « » A # t £ D H ft f* ^ - ~y h 2 2 OfttJfA2ft/ctmA#it5?Jr- 

— 1 y 2 3 ot7>?if >/^2 4 o^g?„ 0 oatinA ; g|iS | Jh-^y2 

3 0±£I12n3o £4t- 3 0 0 Stl7>?*Aty^-240OSItt 1 5Sfl^-y-fe 
-^ 2 6 0 , Bg-SfS © Bf-i- (cryptographic Cipher)^- (CK) 2 9 0 , R 1 p tt ( I n t 
egrity) ( I K ) 3 1 0 S ft ft 2 5 0 t J; D f ffl S ns 0 CK 

2 9 0 t I K3 1 0 £lZ&mfo3L—V h 2 2 0 td £1 2 tl ? 0 
[0019] 

3 W] f* ^ — V h 2 2 Ot'li, ili)^0^7t-;cf|2nfe( i ntended) g IfX A © t 
iDSi^niSi^lc, CK 2 9 0 (if|fta-7E 2 2 0 tVS2 1 0 il © S © jl M 

* Bf ^ f fc f S ft a6 t ffi ffl * ft 3 d i: ^ # S 0 fkt^< H^ + -*Sfflt5/i: 

46©s«t±, *5e0^©«SAtiirg^ft, ^iM^ntco^tiisisnft, sit©* 

BI#^m)IIS^Sl09/1 43, 4 4 1 ^, 1 998^8M28B£lffi, ^MI/rBf^ 
ftX t- 'J-ABg^^iSt-gfcJ&O^gfcSI "Method and Apparat 
us for Generating Encryption Stream Ciph 

ers"j tfSiJtltl^o fficff ^fft:S«tt c ©0? tlH^^ftftUBfi^HclBHt^ 

[ 0 0 2 0 ] 

I K 3 1 0 f± ^ -y-fe - V M $1 W ^ (MAC) * 56 ^ f 3 ft *6 t ffi ffl 2 ft S d t ft V # , d 
d M A C f± ^ fS ^ v -fe - 7 \y - A ^ # % (D S * # Z ^ * S ft ft d i: * 5S zb % ft 46 
lc , % L T © ^ -y -fe - & fr m it \c m. M * ft * fro ft d t * B fr ib Z> ft 46 t , g fS ^ -y 
•tr-^tfrfAn^ftSo M A C S ft 46©S«t±, *%i©ISA£II?n, ?[ffl 

^ftTd©npt|fl^3ASftft, tH)Hffi©7(eB#fFtH)HS-^'^0 9/ 3 7 1 ) 1 4 7 ^1, 1 

9 9 9 f 8fl9Bjfffl, ^^h;i/r^-y^-^fifiEffF^^5e^-rsft46©7?rSi;SB " 

Method and Apparatus for Generating a Me 
ssage Authentication C o d e " J fE £ ft T S 0 §§ flE fff -*t 

* ?e ^ -r s ft 46 © ffi © s « f± <i <d op t iH a 2 ft ft it ffi m m <d m m \c m m * r is t ~c tn 
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tsfflsnsc^^-ptSo £ -d x , d © ffi ic m ffl * ft /= £ ? * « m " m * " f± ^ a (h ^> 
x r h ic is ^ r it ffi * n t# s ^ -r n ^ © §s IE x ^ - h <d b ts % m t 0 

[ 0 0 2 1 ] 

ftfcDt, I K 3 1 Ofilf ^■j/'fe-^tg^lcS/'cii-StSisn^igO If IS t a 
~^AcMM 3 4 0 M^T 3 ftfetifflSnS £ £ -Z?#3o iSM*£f&£T3 Ac 

H 5 , 9 4 3, 6 1 5 ^ , # 4 Y )V T to H a {§ >> X r A ^ T §g fl -fe ^ a U r ■< * fil ffi 
t^ftiiO^SfcSI "Method and Apparatus for Prov 

iding Authentication Security in a Wirel 

ess Communication S y s t e m " J t fE ;SS ^ ft T ^ § 0 fl fiE II 3 10 

4 0 t± I K 3 1 0 # ^ ft f* a ^ -y h 2 2 0 S> © ^ v -t? - v> 3 5 0 ii ffi & t> * § m -y =J 
3. (hashing element) 3 3 0 <D & f] T° %> Z> 0 flflg^3 4 0 t * V K ~ 3 5 0 t li 
ffiL M IC £ D (over the air) V S 2 1 0 £If^ft§ 0 

[ 0 0 2 2 ] 

|2tl5tl«J;^<:, Bf mt*— 2 9 0 £ — (integrity key) 3 1 0 t li tin A 

# ft JS'J r- - ? > 2 3 0 % & ft f* a - -y h 2 2 OtjUISn, ^ ft f± WL m t £ D ^7 U -y 
^ • r ^ -fe 5 ^ — 3 y (publ ic dissemination)© Ac 46 © T — ^ 7 U — A^f^L^HtS 

0 dfiD8fl5f±j£"5 Ktt2 A (eavesdropper) 55 Iti D^CDcfcd&^r-fiDffiffifc&Sf 

5 © « <* d i; ^ # § - 7?^ , d © S « f± n - 9 • ->i;Hi:j;3SSi!i^©Sl*liffi 

L%t^ 0 n - ^ • i/ x;Krogue shell) C K 2 9 O fc I K 3 1 0 t * Sit AttS i ^ 20 
L T ^ ©fl^ (D £ 5 %^-©#ft£r n ;1/ ^ * U t> -Jff f 3 (purging) £ D f± 

7? & « , H ft {* a ~ -y h 2 2 0tfffi©ffiB'\©gM*-£gMf3cfc5fc7n?7i>'f3 
aUSS. C K 2 9 0 £ I K 3 1 0 t li ^ (D ^ , »A#t«PS©*^ilfS^^IEtjA@ 
f S (bi 1 1) Ac 46 t fgffl 2 n S d t ft X # S o l-A->XfA 2 0 0 "Z? S££ 3 ft 7 > A 
ty/^-IA ^ItiC^^^ftAc^-^ffiAffl^C^^fSffl^ftSii^C^dt, ^sgs 
A: S (in a manner that is insecureMSffl '>Xr A tfe^T, d © n — ^ • i/x 

[ 0 0 2 3 ] 

n - if • >> x ;l/ £ « t fl A T f« II f 3 1 ft ffi ft f± ^ » A # H g'J h - ^ y © jf A M L t f± 30 

htj;DB^^ftf#*^«?S«^5e^-rSA:46t, 7°n^r-y^i;i]nA#il 

[ 0 0 2 4 ] 

83 li M ji f§ j/ x r A t T tin A # © n - * ;l/ fl fl ^ H tf T S Ac 46 © 1 ft ffl ^ H ^ H 
d ©^ffi^H^tt, )aAfi9Jh-^y 2 3 0(ilifta-7 h 2 2 Otl^tt 

6 ^ ^ - t S ^ Ac U II JS ^ * 5S ^ f S £ d t 7° n ^ =t h, ^ ft 3 0 L fe An A # 
t <t D ffi ffl * ft Ac ^ ft f* a ^ -y h ^ n - 9 - x ;l/ ft ti\ ^ © n - ^ • >> x ;!/ f± ii IE 

* m m js ^ * b s -r s <i t ii v # * ^ o 

[ 0 0 2 5 ] 

H 2 t fE £ ft Ac A: ?S i: IrI fit t ^ ft f* a - -y h 2 2 o li tin A # ft Wl h - ^ > 2 3 0 40 
SfS^ftS I K3 1 OtVS 2 1 0tI5tlMt^7i?-^ il t S -5 t/^ Ac W M ^ f§ 
tt§„ LfrL&tfZ, 1 llf Itii, s « m ^ li V S ic li m * ft * ^ o s « m ^ n tin 

a # n gij h - * y 2 3 o ic m * ft r , - ^ g « m ^ % ^ t s Ac 46 1 ^ tm ^ - t - m t fs 

ffl?tl5o -^g^f§^t±^ftf*a--y h 2 2 Oti^fl, ^ft«M© Ac 46©V S 2 

1 ot-^i^i^siiiicsftSo 

[ 0 0 2 6 ] 

hs 2 o oti7y^Afy^- 2 4 0 i;jmA#Mh-7y±tfSf#2ftAcS^-©a 

Hta^^Ac^iIiJjS« : (XRES) 2 7 0 t^^Stg. 7 > t 2 4 0 t X R 

E S 2 7 0 t li V S 2 1 Otlf^n^o HS 2 0 OilVS 2 1 0 h <D <DM it HW\ I 

m 3S * ft Ac ?3 S n M t * ft 3 o V S 2 1 oa||f*a^7l-2 2 Ot^^At^^- 50 
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2 4 O^IfLT, flfta^7 h 2 2 0 5If^ 7 2 6 0 Oifl?:iO„ V&M 

— V 2 6 0fcXRES 2 7 0 taVS2 10fOi:tSl? 2 8 0 flt|?nSo 
L fe fit M * V -fe - zs 2 6 0 t X R E S 2 7 0 t ^ V -y f- f ft f£ , V S 2 1 0 (if ffta; 
-y h 2 2 Ot^-H'X^fiffiLtlj-go 
[ 0 0 2 7 ] 

ft f* a - -y h 2 2 0 f± m A # t £ K> ft f* a =. y h 2 2 0 t M ? W t a IS * ft tc M A # 

M h - ^ > 2 3 oiL7y?ity^-2 4 o^eitSo o o f± in A # Hi g'J 

h-^ y 2 3 oitii^ns. s^^-3 o o i;^y^A-^y/^-2 4 0 t con^nB 

f,^7-b-> > '2 6 0 , Bg ^ ^ - ( C K ) 2 9 0 , |jt ^ 14 ^ - (IK) 310, SffUIM 
M^-(UAK) 3 2 OS^SfSftfet^-^S^Z 5 OtiDffflSnSo C K 2 10 
90fc I K3 1 Ottiflfta^7l-2 2 0 t -g 51 2 ft § 0 
[ 0 0 2 8 ] 

llftl^yl-nOf^ C K 2 9 Otiiif-^7L^-A (|3tgg*f) ^Bf^fft 

t^fti&tffflsnso i K3 i o nm&m^ 3 4 o^^sti/tj&tffflsnso w * 

it 3 4 0 li I K 3 1 0 tll*a; 7 1- 2 2 0 fr^ 7 t-? 3 5 0 it, A7'>a 
S It (0 J; 9 % , Bf ^1 ft M W (encrypt i on operat i on) S tc f± 7a [nj M 1¥ (one-way operation 
) £ffffiT3W£f§£3g3 3 0©(H;ft-Z?&3 o g«M3 4 0i±tinA#ft>JJr--^y2 3 
OtSfSnS. tin A # ft >JJ h - ^ > 2 3 0 T\ f«i^ 3 4 0 tUAK 3 2 0 t(i-^ 

mm 3 7 oi&^stsftj&ti^^s^a 6 otiiiijn^o -^m^m^3 7 

0(iflfta;7l- 2 2 0 t 1 ^LTV S 2 1 Otli^tl, ? C ? ii tUif 3 8 0 (± 20 

tin A # © 7 ^ r y r ^ r ^ M "f S 0 M II ? 3 8 0 i± g « {§ ^§ 3 4 0 t-^Km^m^ 

3 7 o t%n^.r % z tic £ <o w>m%mi$T % z t^v ^ % o ftb'jt, 3 8 0 

l±&mfo3.-y h 2 2 0 ^?>W*M^3 4 O^f it? C fctf ft, -^S«fS^f3 7 0 
[ 0 0 2 9 ] 

g « M 3 4 OSlfVS 2 1 ^tW*M^3 7 0 © M i± , 3 3 % K « t £ D 

31 2 ft f# § 0 1 ft ffi ft i± , l^llf 3 8 0 (i*-A->Xfi 2 0 0 ^f.OUAK3 

9 0 R lit 14 3r - * S {§ "Z? # S o & IE * ? 3 8 0 f± $ ^ ft f* a - y h 2 2 0 £ ^ y 

tfffl2tl?Li:tfT-§?„ 30 
[ 0 0 3 0 ] 

tin A # ft >JJ h - ^ > 2 3 0ft©g«5i§^#§3 6 0 (i ^ t 'J t 7°n -fe 7 ^ t i ? c t ^ 
"c? # , cCT-7°nt7*a^5^34Si^fffltTA*^Mf Si^tilS^nSL 
fc^RTtg-efeSo eft £ ©S«t±Bf ^fftSfti, ^7->ali, SfciiJNSiff©!^^ 
&3<i£tf-Z?#3 0 l ffl £ L T , tia A # it JS'J h - * > t <t 5 ft M 2 ft f# 3 1 S « f± , 19 
9 4 fp 5 ft , a » If IS © JI® *P ( F I PS) PUB 1 86, "f-f^^H«Sf ( D i 
gital Signature Standard)" tt'^t&IJtlfc, S4/\7 

•>a7;i/3'JX*A ( s h a ) f$5o tin A # ft h — i 7 yti D ft fr 2 ft f# s fe 5 1 -o © 

Kiii, 1 9 7 7 $1H, F I PS P U B 4 6 t fe^ T&fi 2 tl f:, f — $ ^ ^ \tW-M 

( D E S ) d <D ffi "Z? {£ ffl 2 ft £ d , M " Bf ^ f fc " Ciffl»«Jf Ltiff 40 

[ 0 0 3 1 ] 

^-f 4^ 2 5 0feSfc^€'Jt7°nt'ytt5:ix.§i:ttf-ptSo ft Kl t , 1 ft M 
#-©7°n^-y^^g«56^Sg3 6 0 i; ^ - 56 £ #§ 2 5 0 i:©M^MTSJ; 
7t|i?tl5LJ:^f-?S„ ^fIt±^fiES?3 8 0 H3] C A * ^ C £S S ^ ft If L T 
, If W 2 ft /c tf £ g {§ * ft tf i: * it m f S cl £ t j; D H ff * ft S d £ ^ # S o 
[ 0 0 3 2 ] 

±fH^ffi)Btl© ( i;Df¥lffl*fHat ; tt, i^^4gg 3 3 0 iiCOif t HM A C - S H A - 1 
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tfli^tlfto ^ V is a ^ - X (D M A C s ( H M A C s ) © M i± , WaJC"*vte — i?M 
E©f;i6©^-^y^A7>'aIi (Keying Hash Functions f 
or Message Authent i cat ion) ", ^^b^F, Bg -if $c #j (C ry 
ptology) tfcW-Sjt^-Bg-Sf (Crypto) 9 6llg, 3>^a-^ • tl'xyX 1 109i 
, X 7° U > 7J - <y 7 - 7 ?\ 1 9 9 6 ^tl5lt5il/-F, fitlOltSLttff §5 
o HMACii^ 2Xf 'yyffiltfe^t, SHA-lOi^^ Bg ^ ft -y i/ a « |g # f£ 
fflfSMACX^F-A-efeSo HMAC-SHA-IX^F-Afii, ^ > ^ A & M ^ 
-t±S HA- 1 S tg * W ffl ft L , * tlli * <D & * V * - i? <D 1 ^ i? x X h * £ $ f 3 (p 
roduce) tc 46 t f£ ffl 2 ft S 0 C ©^-(i? Oil 1 «^V>>'iX 1 ?V v'iX F^t 10 
T 3 J; d S H A - 1 * B W ffl f fc T 3 46 t f£ ffl 2 ft 3 o LC$2C^i/*iXKi 

# ^ -y -fe - i? lc ft An 2 ft 3 "Z? 5 5 M A C^gfitS. d © ffi t IE $ * ft /c ft M JB ft "Z? f± 
, » A # it SLl h - 7 > 2 3 0 t £ D £ 2 ft S 14 ^ - (IK) ft , SHA-1*M 
ft L T ^ S 7 > ^ A & $5 ffi ^ - t L T f£ ffl 2 ft 3 d £ & V # S 0 B 4 ft, tin A # ft g'J h 
-^^A^Ci^S^-tJ; •JffllftJn^iilfiOHMA C©Il<OJg|t, U I M 

M^-tj; <o w m it z n % m x^g mm h - ? y fa (D H M A C©f 10^lJ:?:g^t? 

[ 0 0 3 3 ] 

B4tt'^t, HS 2 0 0 li7>?it>^-2 4 OiltinA^liffJh-^^Z 3 0 ±lcU 

wznrcW®m%&<D%imfcM-3^rc¥ffljfc& ( x r e s ) 2 7 0 t * £ -r s 0 ?y?k 20 

ty/^-2 4 0 tXBE S 2 7 OtiiVS 2 1 CMC {§ 2 ft 3 o H S 2 0 0 t V S 2 1 0 

t <D fS <D M it f± m 1 t IH a * ft 7? ?£ n M t * ft 3 o V S 2 1 0!illfta-yl~2 2 
0IC7>^it>^- 2 4 0 ^ HI L t , & ft f* a - -y h 2 2 0 S> © fit fl * ~y -t? - v> 2 
6 0©Sf^f O 0 IfJ7t-i>'2 6 0 J:X R E S 2 7 0 tttV S 2 1 Of (Ditf S? 

2 8 0 it $e 2 ft £ o L fe fit fl * -y -fe - 2 6 0 tXRE S 2 7 0 il ^ V -y f - f ft «\ 
V S 2 1 0ftfifta^7 h 2 2 Oic9--ex^41fttLin^So 

[ 0 0 3 4 ] 

h 2 2 Oft, UaA%fc£*)&W}fo3--v h 2 2 0 t M ? W t a IS * ft tin A 

# ft 5?J h - 7 > 2 3 0 t7>nt>/^-2 4 O^rfEii-fSo S^^-3 0 Ot±tinA#li 

2 3 oitii^ns. o ot7>l'Aty^-2 4 0 tosiii 30 

, B M * V "fc - V 2 6 0 , Bf ^ f t - ( C K ) 2 9 0 , £jt ^ 14 ^ - (IK) 310, & 
U I Mflfl^- (UAK) 3 2 0M^-fS/ci6t^-5i§^#§2 5 Ot^DfSffl^ftSo 
CK 2 9 0fc] K3 1 0 tiiflfta^y h 2 2 0 tfil^tlSo 
[ 0 0 3 5 ] 

||fta^7 h 2 2 OfH, C K 2 9 0 ftlff 7 (|4tagg*f) ^ Bg 

^fttSftfttiffljnSo I K3 1 Ot±g«56^#g3 3 0fr?)Mf§^3 4 0^56^^ 
S/ci6tfgM^ft§ 0 g^56^#§3 3 OttS HA - 1 OiMt<fc^T^7-b-^ 2 6 0© 
g&££$T3cfc5fc;f§)£3ft3 0 S H A - 1 a 7 -> a K3 1 Ot^DWfflft^ 

ft S o 

[ 0 0 3 6 ] 40 

^ -y -fe - V 2 6 0 5:1 Itg S HA- 1 /\ -y a S tg © IS H <fe S m it ^ 3 4 0ft, An 
A#liS l Jh-^>2 3 0 t)Mf§^ft§ o tinA ; g|iS l Jh-^>2 3 0 T ; , S^fS^f3 4 0 i; 
UAK 3 2 0fcti 1 f 3 6 0 ti 7 ftl^la, U I M ^ y -t? — v> §g IE f?f ^ (UM 

AC) 3 7 0 -pfe?g«fl^3 4 OiDSI^SsEt? (generate) 0 S^fl^S53 6 0 feS 
fcSHA-lA7'>all*lIt«J;7l<:|IJti«o LfrL&tf£, d©S|gt±^© 
III K3 1 0ivtt&L5UAK 3 2 0 ^ L T f/Jl ft 2 ft § „ 
[ 0 0 3 7 ] 

UMAC 3 7 0 ti||fta;yF 2 2 0fcVS2 1 OttglJjl, ^d-^^flS^SS 
OtttinA^CT^ryr^r^^flfiE-rSo MH?3 8 0t±g«fS^3 4 0 fcUMAC 

3 7 0 il^B^-TSdiit^D^fiE^iiJiJc-rSo ftbDt, ^fIS?3 8 Oftftfta; 50 
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y F 2 2 0 ^ ^m^is^ 3 4 O^rgfaLT, UMAC 3 7 0 O*^ SttS C 
[ 0 0 3 8 ] 

H 5 i± ft ffi JF^ ft © — fSffc^nfci^^H^TS^n-^-h^fe^o X r -y 7° 5 0 Of 
, mm f* a - -y F it m m % S * T 3 ^ -y -tr - ^ * ^ T 3 0 X r -y 7° 5 o l -z? , Hft f* a 
- -y F It tin A # ft g'J F - ? y £ * * L © |jt 14 3r - (IK) £ S {§ f 3 o X r -y 7° 5 0 

5i§ £ #§ (D m -y i/ a S tg © 7' n y ? -y- X V h Z , Ff?(pads)„ Hl^ifa, 

^- t± ft 2 b t -tf n /\ y F 2 ft £ (zero-padded) ^ ttff t« 0 ffl©IlJflT(±, ^- 

^OfctacOXf 'y^lif »SJn§i:t* s f tSo X r -y 7° 5 0 4 , r\ y F 2 ft tc I 
K f± §g |E * & S £ T 3 ^ -y -fe - is t M IS 2 ft 3 o A7F2tifcI K i; ^ -y -fe - ^ i; © 3S IS 

r ~y 7° 5 0 5 V m ft 2 ft 3 o 1 Itlltli, XORiffOfiiiii^tyS^fltSIf? 

£ £ & £ fcf ^ 2^)45 ffiffl t jif Lt (for further use) ifX D ffi 2 ft S (recalled) Ltfff 

# 3 o 

[ 0 0 3 9 ] 

fe L fe U I M M II - ( U A K ) ffi ffl * ft 3 J; d 35 ft ti\ f © t 7° n ^' 7 A 7 o - H 
X r -y 7° 5 1 0 tcIC. fe L fe U A K ffi ffl * ft * ^ £ 5 35 ft ti\ f © t 7° n ^ 7 A 7 20 
n-(iXf77°5 2 OtIJfo 
[ 0 0 4 0 ] 

X r -y 7° 5 1 0f\ X r -y 7° 5 0 5 Z <D M ft 2 ft ^ v -fe - ^ f± ira A # ft g'J F - ? y t 
g {§ * ft 3 o X r ~y 7° 5 1 1T\ U A K & Wt ic ft 2 b V % ft ti\ tin A # m Wl h - ? y H 
U A K ^ I J b t 7 Ft §0 ^ -y F 2 ft /c I K It , ^ © ^ -y -fe - if M it -fe -y i/ a y © 
ISfc§SSE£&S£T3B?^ Bfffl©/c6©^tytii?n§Lttfft§o X r -y 7° 
5 1 2T\ / W K 3 ft I K t m ft * ft ^ ~y * - i? t It M IS 2 ft T , W*f&£3§fcAft 
2tl§o S«5e^#gt±, Xf 77"5 1 SfSHA-lOJ;^^ Ay 

^tiiMSo xr-y7°5 1 4f\ m&^^mtDft^itmxmmmv - v yfr t>mm 

fta^7 Ftif^nSo 30 
[ 0 0 4 1 ] 

X r ~y 7° 5 2 0 T\ IrI C lit -n 14 ^-ttffitl^Jtlfc^ -y -fe — 5:M7>t? (rehash) fc 
46 t M ^ ft s o X r -y 7° 5 0 5 © ID ^ v 2 ft ^ -y -fe - f± ^ ft f* a - -y F \HW><DW, 
2 (D m % 5i§ ^ #§ t m Z ft S o & 3 ^ f± t> <0 t , ID ^ v 2 ft /c ^ y -fe - ^ f± X r ~y 7° 5 0 5 

©i^fs^tBSA^ntfej;^. t l t 1 mom-sit*-® 2 ~d<d^ y is a mmic % 

^tfffl?n?i5 & ft ti\ ^ © B? d © |jt ^ 14 ^ - f± y is 3. ^ #§ © # ^ ^ S * S tf 
W ffl ft * ft 3 £ 5 t ^ M * ft tf % £ * ^ o M Z. ti\ ^A7->aXf 77"to^t, |jt 
14 ^ - f± S 7? i: ft 2 b © , glic, SfeBgifc; © ^ f ft 2Mc e -y F - 7 ^ 
X(bit-wise)^f^tirJ^ftS d ttfftSo d ©7?rS ^fSffl L T, 1 -D <DU&&* — <D fytf 
m A # m Wl h - ^ y \c j; D £ * ft 3 d t & m ^ 3d S o 40 
[ 0 0 4 2 ] 
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LOCAL AUTHENTICATION IN A COMMUNICATION 
SYSTEM 

BACKGROUND 

I. Field of the Invention 

The present invention relates to communication systems, and mor 
particularly, to local authentication of a communication system subscriber. 



II. Background 

The field of wireless communications has many applications including, 
e.g., cordless telephones, paging, wireless local loops, personal digital 
assistants (PDAs), Internet telephony, and satellite communication systems. 
A particularly important application is cellular telephone systems for mobile 
subscribers. As used herein, the term "cellular" system encompasses both 
cellular and personal communications services (PCS) frequencies. Various 
over-the-air interfaces have been developed for such cellular telephone 
systems including, e.g., frequency division multiple access (FDMA), time 
division multiple access (TDMA), and code division multiple access (CDMA). 
In connection therewith, various domestic and international standards have 
been established including, e.g., Advanced Mobile Phone Service (AMPS), 
Global System for Mobile (GSM), and Interim Standard 95 (IS-95). In 
particular, IS-95 and ils derivatives, IS-95A, IS-95B, ANSI J-STD-OOS (often 
referred to collectively herein as IS-95), and proposed high-data-rate systems 
for data, etc. are promulgated by the Telecommunication Induslry Association 
(TIA) and other well known standards bodies. 

Cellular telephone systems configured in accordance with the use of 
the IS-95 standard employ CDMA signal processing techniques to provide 
highly ellicient and robust cellular telephone service. Exemplary cellular 
telephone systems configured substantially in accordance with the use of the 
IS-95 standard are described in U.S. Patent Nos. 5,103,459 and 4,901,307, 
which are assigned to the assignee of the present invention and incorporated 
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by reference herein. An exemplary system utilizing CDMA techniques is the 
cdma2000 ITU-R Radio Transmission Technology (RTT) Candidate 
Submission (referred to herein as cdma2000), issued by the TIA. The 
standard for cdma2000 is given in the draft versions of IS-2000 and has boon 
5 approved by the TIA. The cdma2000 proposal is compatible with 13-95 
systems in many ways. Another CDMA standard is the W-CDMA standard, 
as embodied in 3 rd Generation Partnership Project "3GPP" . Document Nos. 
3G TS 25.21 1 , 3G TS 25.212, 3G TS 25.213, and 3G TS 25.214. 

Given the ubiquitous proliferation of telecommunications services in 

10 most parts of the world and the increased mobility of the general populace, it 
is desirable to provide communication services to a subscriber while he or she 
is travelling outside the range of Ihe subscriber's home system. One method 
of satisfying this need is the use of an identification token, such as the 
Subscriber Identity Module (SIM) in GSM systems, wherein a subscriber is 

15 assigned a SIM card that can be inserted into a GSM phone. The SIM card 
carries information that is used to identify the billing information of the party 
inserting the SIM card into a mobile phone. Next generation SIM cards have 
been renamed as USIM (UTMS SIM) cards. In a CDMA system, the 
identification token is referred to as a Removable User Interface Module (R- 

20 UIM) and accomplishes the same purpose. Use of such an identification 
token allows a subscriber to travel without his or her personal mobile phone, 
which may be configured to operated on frequencies that are not used in the 
visited environment, and to use a locally available mobile phone without 
incurring costs in establishing a new account. 

25 Although convenient, the use of such identification tokens to access 

account information of a subscriber can be insecure. Currently, such 
identilication tokens are programmed to transmit private information, such as 
a cryptographic key used for message encryption or an authentication key for 
identifying the subscriber, to the mobile phone. A person contemplating the 

30 theft of account information can accomplish his or her goal by programming a 
mobile phone to retain private information after the identification token has 
been removed, or to transmit the private information to another storage unit 
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during the legitimate use of the mobile phone. Mobile phones that have been 
tampered in this manner will hereafter be referred to as "rogue shells." 
Hence, there is a current need to preserve the security of the private 
information stored on an identification token while still facilitating the use of 
5 said private information to access communication services. 



Summary 

A novel method and apparatus for providing secure authentication to a 
subscriber roaming outside his or her home system are presented. In one 
10 aspect, a subscriber identification token is configured to provide 
authentication support to a mobile unit, wherein the mobile unit conveys 
information to the subscriber identification token for transformation via a 
secret key. 

In one aspect, an apparatus for authenticating a subscriber in a 

15 wireless communication system is presented, wherein the apparatus can be 
communicatively coupled to a mobile station operating within the wireless 
communications system. The apparatus comprises a memory and a 
processor configured to implement a set of instructions stored in the memory, 
the set of instructions for selectively generating a primary signature based 

20 upon a key that is held private from the mobile station and a secondary 
signature that is received from the mobile station. 

In another aspect, a method for providing authentication of a subscriber 
using a subscriber identification device is presented. The method comprises 
the steps of: generating a plurality of keys; transmitting at least one key from 

25 the plurality of keys to a communications device communicatively coupled to 
the subscriber identification device and holding private at least one key from 
the plurality of keys; generating a signature at the communications device 
using both the at least one key transmitted to the communications device and 
a transmission message, wherein generating is implemented by hashing a 

30 concatenated value formed from the at least one key and the transmission 
message; transmitting the signature to the subscriber identification device; 
receiving the signature at the subscriber identification device; generating a 
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primary signature from the received signature, wherein the generating is 
implemented by hashing a concatenated value formed from the at least one 
private key and the signature received from the communications device; and 
conveying the primary signature to a communications system. 
5 In another aspect, a subscriber identification module is presented. The 

subscriber identification module comprises a key generation element and a 
signature generator configured to receive a secret key from the key 
generation element and information from a mobile unit, and further configured 
to generate a signature that will be sent to the mobile unit, wherein the 
10 signature is generated by concatenating the secret key wiih the information 
from the mobile unit and hashing the concatenated secret key and 
information. 

Detailed Description of the Drawings 

15 FIG. 1 is a diagram of an exemplary data communication system. 

FIG. 2 is a diagram of a communication exchange between 
components in a wireless communication system. 

FIG. 3 is a diagram of an embodiment wherein a subscriber 
identification token provides encryption support to a mobile unit. 
20 FIG. 4 is a diagram of an embodiment wherein a hashing function is 

used to generate an authentication signature. 

FIG, 5 is a flow chart of a method to hash a message in order to 
generate an authentication signature. 

25 Detailed Description of the Embodiments 

As illustrated in FIG. 1 , a wireless communication network 10 generally 
includes a plurality of mobile stations {also called subscriber units or user 
equipment) 12a-l2d, a plurality of base stations (also called base station 
transceivers (BTSs) or Node B) 14a-14c, a base station controller (BSC) (also 
30 called radio network controller or packet control function 16), a mobile 
switching center (MSC) or switch 18, a packet data serving node (PDSN) or 
internetworking function (IWF) 20, a public switched telephone network 
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(PSTN) 22 (typically a telephone company), and an Internet Protocol (IP) 
network 24 (typically the Internet). For purposes of simplicity, four mobile 
stations 12a-12d, three base stations I4a-14c, one BSC 16, one MSC 18, and 
one PDSN 20 are shown. It would be understood by those skilled in the art 
5 that there could be any number of mobile stations 12, base stations 14, BSCs 
16, MSCsIS, and PDSNs 20. 

In one embodiment the wireless communication network 10 is a packet 
data services network. The mobile stations 12a-12d may be any of a number 
of different types of wireless communication device such as a portable phone, 

10 a cellular telephone that is connected to a laptop computer running IP-based, 
Web-browser applications, a cellular telephone with associated hands-free car 
kits, a personal data assistant (PDA) running IP-based, Web-browser 
applications, a wireless communication module incorporated into a portable 
computer, or a fixed location communication module such as might be found 

15 in a wireless local loop or meter reading, system. In the most general 
embodiment, mobile stations may be any type of communication unit. 

The mobile stations 12a-12d may be configured to perform one or 
more wireless packet data protocols such as, for example, the ElA/TlA/IS-707 
standard. In a particular embodiment, the mobile stations 12a-12d generate 

20 IP packets destined for the IP network 24 and encapsulate the IP packets into 
frames using a point-to-point protocol (PPP). 

In one embodiment the IP network 24 is coupled to the PDSN 20, the 
PDSN 20 is coupled to the MSC 18, the MSG 18 is coupled to the BSC 16 
and the PSTN 22, and the BSC 16 is coupled to the base stations 14a-14c via 

25 wirelines configured for transmission of voice and/or data packets in 
accordance with any of several known protocols including, e.g., E1, T1, 
Asynchronous Transfer Mode (ATM), IP, Frame Relay, HDSL, ADSL, or 
xDSL. In an alternate embodiment, the BSC 16 is coupled directly lo the 
PDSN 20, and the MSC 18 is not coupled to the PDSN 20. In another 

30 embodiment of the invention, the mobile stalions 12a-12d communicate with 
the base stations 14a-14c over an RF interface defined in the 3 rd Generation 
Partnership Project 2 "3GPP2" , "Physical Layer Standard for cdma2000 
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Spread Spectrum Systems," 3GPP2 Document No. C.P0002-A, TIA PN-4694, 
to be published as TIA/EIA/IS-2000-2-A, (Draft, edit version 30) (Nov. 19, 
1999), which is fully incorporated herein by reference. 

During typical operation of the wireless communication network 10, the 
5 base stations 14a-14c receive and demodulate sets of reverse-link signals 
from various mobile stations 12a-12d engaged in telephone calls, Web 
browsing, or other data communications. Each reverse-link signal received by 
a given base station 14a-14c is processed within that base station 14a-14c. 
Each base station 14a-14c may communicate with a plurality of mobile 

10 stations 1 2a-1 2d by modulating and transmitting sets of forward-link signals to 
the mobile stations 12a-12d. For example, as shown in FIG. 1, the base 
station 14a communicates with First and second mobile stations 12a, 12b 
simultaneously, and the base station 14c communicates with third and fourth 
mobile stations 1 2c, 1 2d simultaneously. The resulting packets are forwarded 

15 to tho BSC 15, which provides call resource allocation and mobility 
management functionality including the orchestration of soft handoffs of a call 
for a particular mobile station 12a-12d from one base station 14a-14o to 
another base station 14a-14c. For example, a mobile station 12c is 
communicating with two base stations 14b, 14c simultaneously. Eventually, 

20 when the mobile station 12c moves far enough away from one of the base 
stations 14c, the call will be handed off to the other base station 14b. 

If the transmission is a conventional telephone call, the BSC 16 will 
route the received data to the MSC 18, which provides additional routing 
services for interface with the PSTN 22. If the transmission is a packet-based 

25 transmission such as a data call destined for the IP network 24, the MSC 18 
will route the data packets to the PDSN 20, which will send the packets to the 
IP network 24. Alternatively, the BSC 16 will route the packets directly to the 
PDSN 20, which sends the packets to the IP network 24. 

FIG. 2 illustrates a method for authenticating a subscriber using a 

30 mobile phone in a wireless communication system. A subscriber travelling 
outside of the range of his or her Home System (HS) 200 uses a mobile unit 
220 in a Visited System (VS) 210. The subscriber uses the mobile unit 220 by 
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inserting a subscriber identification token. Such a subscriber identification 
token is configured to generate cryptographic and authentication information 
that allows a subscriber to access account services without the need for 
establishing a new account with the visited system. A request (note shown in 
5 figure) is sent from the mobile unit 220 to the VS 210 for service. VS 210 
contacts HS 200 to determine service to the subscriber (not shown in figure). 

HS 200 generates a random number 240 and an expected response 
(XRES) 270 based on knowledge of the private information held on the 
subscriber identification token. The random number 240 is to be used as a 

10 challenge, wherein the targeted recipient uses the random number 240 and 
private knowledge to generate a confirmation response that matches the 
expected response 270. The random number 240 and the XRES 270 are 
transmitted from the HS 200 to the VS 210. Other information is also 
transmitted, but is not relevant herein (not shown in figure}. Communication 

15 between the HS 200 and the VS 210 is facilitated in the manner described in 
Fig. 1. The VS 210 transmits the random number 240 to 1he mobile unit 220 
and awaits the transmission of a confirmation message 260 from the mobile 
unit 220. The confirmation message 230 and the XRES 270 are compared at 
a compare element 280 at the VS 210. If the confirmation message 260 and 

20 XRES 270 match, the VS 210 proceeds to provide service to the mobile unit 
220. 

Mobile unit 220 sends the random number 240 to the subscriber 
identification token 230 that has been inserted inside the mobile unit 220 by 
the subscriber. A Secure Key 300 is stored on the subscriber identification 

25 token 230. Both the Secure Key 300 and the random number 240 are used 
by a key generator 250 to generate the confirmation message 260, a 
cryptographic Cipher Key (CK) 290, and an Integrity Key (IK) 310. The CK 
290 and IK 310 are conveyed to the mobile unit 220. 

At the mobile unit 220, the CK 290 can be used to encrypt 

30 communications between the mobile unit 220 and the VS 210, so that 
communications can be decrypted only by the intended recipient of the 
message. Techniques for using a cryptographic key to encrypt 
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communications are described in co-pending U.S. Patent Application 
09/143,441, filed on August 28, 1998, entitled, "Method and Apparatus for 
Generating Encryption Stream Ciphers," assigned to the assignee of the 
present invention, and incorporated by reference herein. Other encryption 
5 techniques can be used without affecting the scope of the embodiments 
described herein. 

The IK 310 can be used to generate a message authentication code 
(MAC), wherein the MAC is appended to a transmission message frame in 
order to verify that the transmission message frame originated from a 

ID particular party and to verify that the message was not altered during 
transmission. Techniques for generating MACs are described in co-pending 
U.S. Patent Application No, 09/371,147, filed on August 9, 1999, entitled, 
"Method and Apparatus for Generating a Message Authentication Code : " 
assigned to the assignee of the present invention and incorporated by 

15 reference herein. Other techniques for generating authentication codes may 
be used without affecting the scope of the embodiments described herein. 
Hence, the term "signature" as used herein represents the output of any 
authentication scheme that can be implemented in a communication system. 
Alternatively, the IK 310 can be used to generate an authentication 

20 signature 340 based on particular information that is transmitted separately or 
together with the transmission message. Techniques for generating an 
authentication signature are described in U.S. Patent 5 : 943 : 615, entitled, 
"Method and Apparatus for Providing Authentication Security in a Wireless 
Communication System," assigned to the assignee of the present invention 

25 and incorporated by reference herein. The authentication signature 340 is the 
output of a hashing element 330 that combines the IK 310 with a message 
350 from the mobile unit 220. The authentication signature 340 and the 
message 350 are transmitted over the air to the VS 210. 

As seen in FIG. 2, the cryptographic key 290 and the integrity key 310 

3Q are transmitted from tho subscriber identification token 230 to the mobile unit 
220, which proceeds to generate data frames for public dissemination over 
the air. While this technique may prevent an eavesdropper from determining 
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the values of such keys over the air, this technique does not provide 
protection from attack by a rogue shell. A rogue shell can be programmed to 
accept the CK 290 and the IK 310, and to then store the keys rather than 
purging the presence of such keys from local memory. Another method to 
5 steal keys is to program the mobile unit 220 to transmit received keys to 
another location. The CK 290 and the IK 310 can then be used to fraudulently 
bill unauthorized communications to the subscriber. This rogue shell attack is 
particularly effective in systems wherein the random number generated at the 
Home System 200 is used in a manner that is insecure, such as the case 

10 when the same generated keys are used for an extended period of time. 

An embodiment that protects against a rogue shell attack uses the 
processors and memory in the subscriber identification token to generate an 
electronic signature that cannot be reproduced by a mobile unit without the 
insertion of the subscriber identification token. 

15 FIG. 3 illustrates an embodiment for performing local authentication of 

a subscriber in a wireless communication system. In this embodiment, the 
subscriber identification token 230 is programmed to generate an 
authentication response based on a key that is not passed to the mobile unit 
220. Hence, if the mobile unit used by a subscriber is a rogue shell, the rogue 

2D shell cannot recreate the appropriate authentication responses. 

Similar to the method described in FIG. 2, the mobile unit 220 
generates a signature signal based upon an IK 310 that is received from the 
subscriber identification token 230 and a message that is to be sent to the VS 
210. However, in one embodiment, the signature signal is not passed to the 

25 VS. The signature signal is passed to the subscriber identification token 230, 
and is used along with an additional key to generate a primary signature 
signal. The primary signature signal is sent out to the mobile unit 220, which 
in turn transmits the primary signature signal to the VS 210 for authentication 
purposes. 

30 HS 200 generates a random number 240 and an expected response 

(XRES) 270 based on knowledge of the Secure Key held on the subscriber 
identification token 230. The random number 240 and the XRES 270 are 
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transmitted to the VS 210. Communication between the HS 200 and the VS 
210 is facilitated in the manner described in Fig. 1. The VS 210 transmits the 
random number 240 to the mobile unit 220 and awaits the transmission of a 
confirmation message 260 from the mobile unit 220. The confirmation 
5 message 260 and the XRES 270 are compared at a compare element 280 at 
the VS 210. If the confirmation message 260 and the XRES 270 match, the 
VS 21 0 proceeds to provide service to the mobile unit 220. 

Mobile unit 220 conveys the random number 240 to the subscriber 
identification token 230 that has been electronically coupled with the mobile 

10 unit 220 by the subscriber. A Secure Key 300 is stored on the subscriber 
identification token 230. Both the Secure Key 300 and the random number 
240 are used by a key generator 250 to generate the confirmation message 
260, a Cryptographic Key (CK) 290, an Integrity Key (IK) 310,. and a UIM 
Authentication Key (UAK) 320. The CK 290 and IK 310 are conveyed to the 

15 mobile unit 220. 

At the mobile unit 220, the CK 290 is used for er 
data frames (not shown in FIG. 3). The IK 310 is used ,to generate a 
signature signal 340. The signature signal 340 is the output of a signature 
generator 330 that uses an encryption operation or a one-way operation, such 

20 as a hashing function, upon the IK 310 and a message 350 from the mobile 
unit 220. The signature signal 340 is transmitted to the subscriber 
identification token 230. At the subscriber identification token 230, the 
signature signal 340 and the UAK 320 are manipulated by a signature 
generator 360 to generate a primary signature signal 370. The primary 

25 signature signal 370 is transmitted to the mobile unit 220 and to the VS 210, 
where a verification element 380 authenticates the identity of the subscriber. 
Tho verification element 380 can accomplish the verification by regenerating 
the signature signal 340 and the primary signature signal 370. Alternatively, 
the verification element 380 can receive the signature signal 340 from the 

30 mobile unit 220 and only regenerate the primary signature signal 370. 

The regeneration of the signature signal 340 and the primary signature 
signal 370 at the VS 210 can be accomplished by a variety of techniques. In 
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one embodiment, the verification element 380 can receive a UAK 390 and an 
integrity key from the Home System 200. When the verification element 380 
also receives the message 350 from the mobile unit 220, the signature signal 
can be generated and then be used to generate the primary signature 
5 element. 

The signature generator 360 within the subscriber identification token 
230 can comprise a memory and a processor, wherein the processor can be 
configured to manipulate inputs using a variety of techniques. These 
techniques can take the form of encryption techniques, hashing functions, or 

10 any nonreversible operation. As an example, one technique that can be 
implemented by the subscriber identification token is the Secure Hash 
Algorithm (SHA), promulgated in Federal Information Processing Standard 
(FIPS) PUB 186, "Digital Signature Standard," May 1994. Another technique 
that can be performed by the subscriber identification token is the Data 

15 Encryption Standard (DES), promulgated in FIPS PUB 46, January 1977. 
The use of the term 'encryption" as used herein does not necessarily imply 
that operations must be reversible. The operations may be non-reversible in 
the embodiments described herein. 

The key generator 250 can also comprise a memory and a processor. 

20 Indeed, in one embodiment, a single processor can be configured to 
accomplish the functions of the signature generator 360 and the key 
generator 250. Verification can be performed by calculating the same result 
from the same inputs at the verification element 380, and comparing the 
calculated and transmitted values. 

25 In a more detailed description of the embodiment above, signal 

generator 330 can be configured to implement a technique referred to herein 
as HMAC-SHA-1. In the embodiment described above, it was noted that a 
hashing function could be used within the signal generator 330 to generate a 
signature signal 340. A description of hash-based MACs (HMACs) can be 

30 found in the paper, 'Keying Hash Functions for Message Authentication," 
Bellare, et al., Advances in Cryptology - Crypto 96 Proceedings, Lecture 
Notes in Computer Science Vol. 1109, Springer-Verlag, 1996. An HMAC is a 
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MAC scheme that uses a cryptographic hash function, such as SHA-1, in a 
two-step process. In an HMAC-SHA-1 scheme, a random and secrei key 
initializes the SHA-1 function, which is then used to produce a digest o1 the 
message. The key is then used to initialize SHA-1 again to produce a digest 
5 of the first digest. This second digest provides a MAC that will he appended to 
each message. In the embodiment described herein, the integrity key (IK) 
310 that is generated by the subscriber identification token 230 can be used 
as the random and secret key initializing SHA-1 . FIG. 4 is a flow chart 
illustrating the implementation of the HMAC in the mobile station, which is 

10 initialized by an integrity key from the subscriber identification token, and the 
implementation of the HMAC in the subscriber identification token, which is 
initialized by a UIM Authentication Key. 

In FIG. 4, HS 200 generates a random number 240 and an expected 
response (XRES) 270 based on know/edge of the private information held on 

15 the subscriber identification token 230. The random number 240 and the 
XRES 270 are transmitted to the VS 210. Communication between the HS 
200 and the VS 210 is facilitated in the manner described in Fig. 1.' The VS 
210 transmits the random number 240 to the mobile unit 220 and awaits the 
transmission of a confirmation message 260 from the mobile unit 220. The 

20 confirmation message 260 and the XRES 270 are compared at a compare 
element 280 at the VS 210. If the confirmation message 260 and the XRES 
270 match, the VS 210 proceeds to provide service to the mobile unit 220. 

Mobile unit 220 conveys the random number 240 to the subscriber 
identification token 230 that has been electronically coupled with the mobile 

25 unit 220 by the subscriber. A Secure Key 300 is stored on the subscriber 
identification token 230. Both the Secure Key 300 and the random number 
240 are used by a key generator 250 to generate the confirmation message 
260, a Cryptographic Key (CK) 290, an Integrity Key (IK) 310, and a UIM 
Authentication Key (UAK) 320. The CK 290 and IK 310 are conveyed to the 

30 mobile unit 220. 

At the mobile unit 220, the CK 290 is used for encrypting transmission 
data frames (not shown in FJG. 4). The JK 310 is used to generate a 
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signature signal 340 from the signature generator 330. The signature 
generator 330 is configured to produce a transformation of the message 260 
through the use of SHA-1. The SHA-1 hashing function is initialized by the [K 
310. 

5 The signature signal 340, which is the result of the SHA-1 hashing 

function transforming the message 260, is transmitted to the subscriber 
identification token 230. At the subscriber identification token 230, the 
signature signal 340 and the UAK 320 are manipulated by a signature 
generator 360 to generate a transformation ol the of the signature signal 340, 

10 which is the UIM message authentication code (UMAC) 370. The signature 
generator 360 is also configured to implement the SHA-1 hashing function, 
However, the function is initialized using UAK 320, rather then IK 310. 

The UMAC 370 is transmitted to the mobile unit 220 and to the VS 21 0, 
where a verification clement 380 authenticates the identity of the subscriber. 

15 The verification element 380 can accomplish the verification by regenerating 
the signature signal 340 and the UMAC 370. Alternatively, the verification 
element 380 can receive the signature signal 340 from the mobile unft 220 
and only regenerate the UMAC 370. 

FIG. 5 is a flow chart illustrating a generalized description of the 

20 embodiment. At step 500, a mobile unit generates a message that requires 
authentication. At step 501, the mobile unit receives an integrity key (IK) of 
length L from a subscriber identification token. At step 502, the mobile unit 
pads the integrity key IK to length b, wherein b is the block size of the hashing 
function of a signature generator within the mobile unit. In one embodiment, 

25 the key can be zero-padded to length b. In another embodiment, the key can 
be XORed with padding constants of length b. If the IK already has length b, 
then this step can be omitted. At step 504, the padded IK is concatenated 
with the message that requires authentication. The concatenation of the 
padded IK and the message is then hashed at step 505 by a signature 

30 generator configured to implement a hashing function such as SHA. In one 
embodiment, the output of the XOR operation is saved within a memory 
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element, and can be recalled for further use if the IK from the subscriber 
identification token remains the same during the communication session. 

If the UIM authentication key (UAK) is to be used, then the program 
flow proceeds lo step 510. If the UAK is not to be used, then the program 
5 flow proceeds to step 520. 

At step 510, the hashed message from step 505 is transmitted to 1he 
subscriber identification token, At step 51 1 , the subscriber identification token 
pads the UAK to length b, unless the UAK is already of length b. The padded 
IK can be stored in memory for reuse when a subsequent message requires 

10 authentication during the communication session. At step 512, the padded IK 
and the hashed message are concatenated and inputted into a signature 
generator. The signature generator is configured to implement a hashing 
function, such as SHA-1 at step 513. At step 514, the output of the signature 
generator is transmitted from the subscriber identification token to the mobile 

15 unit, 

At step 520, the same integrity key is used to rehash the already 
hashed message. The hashed message from step 505 is sent to a second 
signature generator within the mobile unit. Or alternatively, the hashed 
message can be re-inserted into the signature generator of step 505. If one 

20 integrity key is to be used in two hashing processes, then the integrity key 
must be altered so that each of hashing generators is initialized with a 
different value. For example, for each hashing step, the integrity key can be 
bit-wise added to either constant value ci or constant value both of length 
b. Using this method, only one integrity key needs to be generated by the 

25 subscriber identification token. 

It should be noted that the more secure embodiment is the 
implementation wherein the second hashing step is performed using the UAK 
at the subscriber identification token. 

The process described in FIG. 5 can be mathematically described by 

30 the equation: 

HMAC(x) - F toketl (U4K, F mobi | e (/K, *)>, 
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wherein F y ( ) represents a hashing function performed at a location Y, x 
represents the original message, UAK and IK are the keys, and a comma 
represents a concatenation. 
5 A subscriber identification token used in a CDMA system or a GSM 

system, also known as an R-UIM or a USIM, respectively, can be configured 
to generate the primary signature signal or UMAC in the manner described 
above, i.e., all messages generated by the mobile unit are encrypted and 
authenticated. However, since the central processing unit in such tokens can 

10 be limited, it may be desirable to implement an alternative embodiment, 
wherein a weight of importance is assigned to a message frame so that only 
important messages are securely encrypted and authenticated. For example, 
a message frame containing billing information has more need for increased 
security than a message frame containing a voice payload. Hence, the 

15 mobile unit can assign a greater weight of importance to the billing information 
message frame and a lesser weight of importance to the voice message 
frame. When the subscriber identification token receives the signature signals 
generated from these weighted messages, the CPU can assess the different 
weights of importance attached to each signature signal and determine a 

20 primary signature signal for only the heavily weighted signature signals. 
Alternatively, the mobile unit can be programmed to convey only the 
"important" signature signals to the subscriber identification token. This 
method of selective primary signature signal generation increases the 
efficiency of the subscriber identification token by lightening the processing 

25 load of the subscriber identification token. 

The embodiments described above prevent unauthorized use of a 
subscriber's account by requiring a more secure transaction between the 
subscriber identification token and the mobile unit. Since the mobile unit 
cannot generate a primary signature signal without knowledge of the secret 

30 UAK, the mobile unit that is programmed to act as a rogue shell cannot 
misappropriate subscriber information for wrongful purposes. 
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The embodiments described above also maximize the processing 
capability of the subscriber identification token by operating on a signature 
signal, rather than a message. Typically, a signature signal will have a 
shorter bit length than a message. Hence, less time is required for the 
signature generator in the subscriber identification to operate on a signature 
signal rather than a transmission message frame. As mentioned above, the 
processing capability of the subscriber identification token is usually much 
less than the processing capability of the mobile unit. Hence the 
implementation of this embodiment would provide secure authentication of 
messages without sacrificing speed. 

However, it should be noted that improvements in processor 
architectures occur at an almost exponential pace. Such improvements 
consist of faster processing times and smaller processor sizes. Hence, 
another embodiment for providing local authentication can be implemented 
wherein the primary signature signal can be generated directly from a 
message, rather than indirectly through a short signature signal. A mobile unit 
can be configured to pass a messaoe directlv to the subscriber identification 
toKen, one witn tne capaomty to generate a primary signature signal quickly, 
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electronic hardware, software, firmware, or combinations thereof. The various 
illustrative components, blocks, modules, circuits, and steps have been 
described generally in terms of their functionality, Whether the functionality is 
implemented as hardware, software, or firmware depends upon the particular 
5 application and design constraints imposed on the overall system. Skilled 
artisans recognize the interchangeability of hardware, software, and firmware 
under these circumstances, and how best to implement the described 
functionality for each particular application. 

Implementation of various illustrative logical blocks, modules, circuits, 

10 and algorithm steps described in connection with the embodiments disclosed 
herein may be implemented or performed with a digital signal processor 
(DSP), an application specific integrated circuit (ASIC), afield programmable 
gate array (FPGA) or other programmable logic device, discrete gate or 
transistor logic, discrete hardware components. A processor executing a set 

15 of firmware instructions, any conventional programmable software module 
and a processor, or any combination thereof can be designed to perform the 
functions described herein. The processor may advantageously be a 
microprocessor, but in the alternative, the processor may be any conventional 
processor, controller, microcontroller, or state machine. The software module 

20 could reside in RAM memory, flash memory, ROM memory, EPROM memory, 
EEPROM memory,, registers, hard disk, a removable disk, a CD-ROM, or any 
other form of storage medium known in the art. An exemplary processor is 
coupled to the storage medium so as to read information from, and write 
information to, the storage medium. In the alternative, the storage medium 

25 may reside in an ASIC. The ASIC may reside in a telephone or other user 
terminal. In the alternative, the processor and the storage medium may 
reside in a telephone or other user terminal. The processor may be 
implemented as a combination of a DSP and a microprocessor, or as two 
microprocessors in conjunction with a DSP core, etc. Those of skill would 

30 further appreciate that the data, instructions, commands, information, signals, 
bits, symbols, and chips that may be referenced throughout the above 
description are represented by voltages, currents, electromagnetic waves, 
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magnetic fields or particles, optical fields or particles, or any combination 
thereof. 

Various embodiments of the present invention have thus been shown 
and described. It would be apparent to one of ordinary skill in the art, 
5 however, that numerous alterations may be made to the embodiments herein 
disclosed without departing from the spirit or scope of the invention. 

WE CLAM: 
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CLAIMS 

1 . A subscriber identification module for providing local authentication of a 
2 subscriber in a communication system, comprising: 

a memory; and 

4 a processor configured to implement a set of instructions slored in the 

memory, the set of instructions Tor: 
6 generating a plurality of keys in response to a received 

challenge; 

8 generating an initial value based upon a first key from the 

plurality of keys; 

10 concatenating the initial value with a received signal to form an 

input value, wherein the received signal is transmitted from a 

12 communications unit communicatively coupled to the subscriber 

identification module, and the received signal is generated by the 

14 communications unit using a second key from the plurality of keys, the 
second key having been communicated from the subscriber 

16 identification module to the communications unit; 

hashing the input value to form an authentication signal; and 

15 transmitting the authentication signal to the communications 
system via the communications unit. 

2. The apparatus of Claim 1, wherein hashing the input value is 
2 performed in accordance with the Secure Hashing Algorithm (SHA-1). 

3. The apparatus of Claim 1, wherein generating the initial value 
2 comprises padding the first key. 

4. The apparatus of Claim 3, wherein generating the initial value further 
2 comprises adding the padded first key bit-wise to a constant value. 
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5. The apparatus of Claim 1, wherein the received signal is generated at 
2 the communications unit by: 

receiving the second key from the subscriber identification module; 

4 generating a local initial valuB based upon the second key; 
concatenating the local initial value and a message to form a local input 

6 value; 

hashing the local input value to torm the received signal; and 

5 transmitting the received signal to the subscriber identification module. 

6. The apparatus of Claim 5, wherein generating the local initial value 
2 comprises padding the second key. 

7. The apparatus of Claim 6, wherein generating the local initial value 
2 further comprises adding the padded second key bit-wise to a second 

constant value. 

8. A subscriber identification module, comprising: 
2 a key generation element; and 

a signature generator configured to receive a secret key from the key 
4 generation element and information from a mobile unit, and further configured 
to generate a signature that will be sent to the mobile unit, wherein the 

6 signature is generated by concatenating the secret key with the information 
from the mobile unit and hashing the concatenated secret key and 

8 information. 

9. The subscriber identification module of Claim 8, wherein the key 
2 generation element comprises; 

a memory; and 

4 a processor configured to execute a set of instructions stored in the 

memory, wherein the set of instructions performs a cryptographic 
6 transformation upon an input value to produce a plurality of temporary keys. 
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11. An apparatus for providing secure local authentication of a subscriber 
2 in a communication system, comprising a subscriber identification module 
configured to interact with a communications unit, wherein the subscriber 
4 identification module comprises: 

a key generator for generating a plurality of keys from a received 
6 value and a secret value, wherein at least one communication key from 

the plurality of keys is delivered to the communications unit and at least 
8 one secret key from the plurality of keys is not delivered to the 

communications unit; and 
10 a signature generator for generating an authorization signal from 

hashing a version of the at least one secret key together with an 
12 authorization message, wherein the authorization message is 

generated by the communications unit using a version of the at least 
14 one communication key. 



12. The apparatus of Claim 11, wherein the subscriber identification 
2 module is configured to be inserted into the communications unit. 

13. The apparatus of Claim 11, wherein the at least one communication 
2 key comprises an integrity key. 



14. The apparatus of Claim 11, wherein hashing is performed in 
2 accordance with SHA-1 . 



15. A method for providing authentication of a subscriber using a 
2 subscriber identification device, comprising: 

generating a plurality of keys; 
4 transmitting at least one key from the plurality of keys lo a 

communications device communicatively coupled to the subscriber 
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6 identification device and holding private at least one key from the plurality of 
keys; 

8 generating a signature at the communications device using both the at 

least one key transmitted to the communications device and a transmission 
10 message, wherein generating is implemented by hashing a concatenated 

value formed from the at least one key and the transmission message; 
12 transmitting the signature to the subscriber identification device; 

receiving the signature at the subscriber identification device; 

14 generating a primary signature from the received signature, wherein 
the generating is implemented by hashing a concatenated value formed from 

16 the at least one private key and the signature received from the 
communications device; and 

15 conveying the primary signature to a communications system. 

16. The method of Claim 15, wherein hashing is implemented in 
2 accordance with SHA-1 . 

17. An apparatus for authenticating a subscriber in a wireless 
2 communication system, wherein the apparatus can be communicatively 

coupled to a mobile station operating within the wireless communications 
4 system, comprising: 
a memory; and 

6 a processor configured to implement a set of instructions stored in the 

memory, the set of instructions for selectively generating a primary signature 

8 based upon a key that is held private from the mobile station and a secondary 
signature that is received from the mobile station. 



(40) 



JP 2004-533174 A 2004. 10. 28 




(41) 



JP 2004-533174 A 2004. 10. 28 




(42) 



JP 2004-533174 A 2004. 10. 28 




(43) 



JP 2004-533174 A 2004. 10. 28 




(44) 



JP 2004-533174 A 2004. 10. 28 



IK from token 







Hash at first 




Hash at second 










generator of MS 


n i 




WW 


UAK is padded 




Rehash at first 




(alternate to "520) 


generator 





|UMACtoMS| 



(45) 



JP 2004-533174 A 2004. 10. 28 



PCT/US 02/16103 



IPC 7 H04Q7/38 H04L9/32 H04L29/06 HOW/32 



IPC 7 HMQ H04L 



"Rouges MS_Shel 1 Treat Analysis" 
3GPP TSG Sfl WS3 SECURITY, 'Online! 
28 - 30 November 2000, pages 1-17, 



Sophia Antipolis. France 
Retrieved from the Internet: 
<URL : http : //www. 3gpp . org/f tp/tsg_sa/HG3_Se 
c ur 1 ty/2 DOOjieet 1 n S s/TSG S3_l 6_Sophi a_Ant i p 
ol1s/Docs/PDF/S3-0007ll.pdf> 
'retrieved on 2OO2-0S-20! 
paragraph '02.2! 




(46) 



JP 2004-533174 A 2004. 10. 28 



INTERNATIONAL SEARCH REPORT I'" wi™ n. 

| PCT/US 02/16103 




«,„,- 






A 


Multiple Signature Eased Certificate 

Verification Scheme" 

B06AZICI UNIVERSITY. 'Online! 

XP002210349 






Retrieved from the Internet: 

<URL: http : //ci teseer .n j nec.com/cache/pape 

rs/cs/2E06/http : zSzzSzuiercan . crape .boun.edu 

.trzSz(levizSzbas98.pdf/a-multiple-signatu 

re-based. pdf > 'retrieved on 2002-08-20! 

abstract 

paragraph '0001! 




A 


"Incorporating UIM into 3G and IHT-2000 
Systems" 

TIA/EIA/IS-808, 'Online! 
- November 2000 (2000-11) XP002210350 
Retrieved from the Internet: 
<URL:http://ww.tiaonline.org/standards/sf 
g/imt2k/cdma2300/TIA-EIA-IS-808.pdf> 
'retrieved on 2002-08-20! 
page 7 -page 25 


w 








HEHROTRA A ET AL : ''MOBILITY ADD SECURITY 
MANAGEMENT IN THE GSM SYSTEM AND SOME 
PROPOSED FUTURE IMPROVEMENTS" 
PROCEEDINGS OF THE IEEE, IEEE. NEW YORK, 
US, 

vol. 86, no. 7, July 1998 (1998-07), pages 

1480-1497, XP000854168 
the whole document 


1-7 


E 


l» 02 054663 A (QUALCOMM INC) 
11 July 2002 (2002-07-11) 
page 12, line 7-13; figure 3 


8-14,17 



(47) 



JP 2004-533174 A 2004. 10. 28 




WO 02051663 P. 11-37-2D02 US 2002091931 Al 11-07-2002 
WO 02054663 A2 11-07-2002 
US 2002091933 Al 11-07-2002 



(48) 



JP 2004-533174 A 2004. 10. 28 



yuy F^- 



(81)fgSB AP(GH > GM > KE > LS > MW > MZ > SD > SL > SZ > TZ > UG > ZM > ZW) > EA(AM > AZ,BY > KG > KZ > MD > RU > TJ > TM) > EP(AT > 
BE,CH,CY,DE,DK,ES,FI,FR,GB,GR,IE,IT,LU,HC,NL,PT,SE,TR),OA(BF,BJ,CF,CG,CI,CH,GA,GN,GQ,GW,HL,MR,NE,SN, 
TDJO.AE.AG.AL.AM.AT.AU.AZ.BA.BB.BG.BR.BY.BZ.CA.CH.CN.CO.CR.CU.CZ.DE.DK.DM.DZ.EC.EE.ES.FI.GB.GD.GE, 
GH.GM.HR.HU.ID.IL.IN.IS.JP.KE.KG.KP.KR.KZ.LCLK.LR.LS.LT.LU.LV.MA.MD.MG.MK.MN.MW.MX.MZ.NO.NZ.OM.PH.P 
L.PT.RO.RU.SD.SE.SG.SI.SK.SLJJJMJNJRJTJZ.UA.UG.UZ.VNJU.ZA.ZM.ZW 



) 2 1 0 7, -9-y • rVxri\ M;W?n-f • F^-T:/ 1 1 



(74)f^IA 100084618 
(74)f^IA 100092196 

(72)5i§f#g i^-y X o^-l7 - S>a-7 
5 O 

(72)5i§f#g n-X ^l/n'J--^- 

^-XF^U75k ^a- • • ^x-;l/Xffl 2 13 7, t;HW^ 
6 

5J104 AA07 KA01 KA03 KA04 NA02 NA05 NA12 NA38 PA01 
5K051 CC07 HH01 HH17 

5K067 AA30 BB04 BB21 DD51 EE02 EE10 HH36 



